Search This Blog

Transferring content from Azure Storage using a secure channel - Aspera On Demand

Storing data in a cloud provider like Microsoft Azure or AWS is trivial. If you have an application that is running on a cloud provider you will start to generate content that is stored there.
Many times this content is private and you need a secure solution to transfer it to different locations around the glob.
One solution for this problem could be Azure CDNs, but in this moment only HTTP protocol is supported. This means that you will need to encrypt the content before sending it on the wire. This might be possible, but if need to transfer 1 TB of data, the encryption and decryption will take some time and will consume resources (especially CPU).
A better solution might be Aspera. Using Aspera services, you will get a transport platform that offer a secure channel (encrypted) to transfer data from one location to another. All the things that you normally need to take into account like bandwidth, security layer over HTTP and so on are handled by Aspera. The communication channel offered by Aspera is reliable and can use your own CDN network (storage nodes) or the one that is provided by them.

There is an interesting add-on in Microsoft Azure Store, that allow us to connect a Storage Account to Aspera. This means that you would be able to transfer content from/to Microsoft Azure Storage to another locations around the world in a secure and fast way. On top of this, you can use Aspera CDN network to have your payload closer to the locations where you need it.
It is important to know that there is no influence to the Azure Storage performance. Connecting Aspera to your storage is like having another client that access your storage. Aspera only encrypt content when it is send on the wire, the end customer will see the content in the same way as it was on Azure Storage.
The add-on for Microsoft Azure Storage is called "Aspera On Demand" and allow any customer to connect to Azure Storage using Aspera services and CDN network. There is an important thing that you need to take into account. You will need to share with Aspera the Storage Account Access Keys. Aspera is also able to work with SAS keys, but in general you will need to share the account access keys.

Aspera can be a good solution when you need a secure transport mechanism to deliver content around the globe, offering a encrypted channel and also a good bandwidth. You might be able to do it yourself, encrypting the content and adding it to public CDNs, but you might need to write a client that is able to decrypt the content and so on. It is a good out of the box solution, but you should be ready to pay for it.

Comments

Post a Comment

Popular posts from this blog

There are cases when you need to check in a service or a controller was register in AngularJS.
For example a valid use case is when you have the same implementation running on multiple application. In this case, you may want to intercept the HTTP provider and add a custom step there. This step don’t needs to run on all the application, only in the one where the service exist and register.
A solution for this case would be to have a flag in the configuration that specify this. In the core you would have an IF that would check the value of this flag.
Another solution is to check if a specific service was register in AngularJS or not. If the service was register that you would execute your own logic.
To check if a service was register or not in AngularJS container you need to call the ‘has’ method of ‘inhector’. It will return TRUE if the service was register.
if ($injector.has('httpInterceptorService')) {
$httpProvider.interceptors.push('httpInterceptorService…

Today blog post will be started with the following error when running DB tests on the CI machine:threw exception:
System.InvalidOperationException: The Entity Framework provider type 'System.Data.Entity.SqlServer.SqlProviderServices, EntityFramework.SqlServer' registered in the application config file for the ADO.NET provider with invariant name 'System.Data.SqlClient' could not be loaded. Make sure that the assembly-qualified name is used and that the assembly is available to the running application. See http://go.microsoft.com/fwlink/?LinkId=260882 for more information.
at System.Data.Entity.Infrastructure.DependencyResolution.ProviderServicesFactory.GetInstance(String providerTypeName, String providerInvariantName)
This error happened only on the Continuous Integration machine. On the devs machines, everything has fine. The classic problem – on my machine it’s working. The CI has the following configuration:

Scope
The main scope of this post is to see how we can run a legacy application written in .NET Framework in Docker.

Context
First of all, let’s define what is a legacy application in our context. By a legacy application we understand an application that runs .NET Framework 3.5 or higher in a production environment where we don’t have any more the people or documentation that would help us to understand what is happening behind the scene.
In this scenarios, you might want to migrate the current solution from a standard environment to Docker. There are many advantages for such a migration, like:

Continuous DeploymentTestingIsolationSecurity at container levelVersioning ControlEnvironment Standardization
Until now, we didn’t had the possibility to run a .NET application in Docker. With .NET Core, there was support for .NET Core in Docker, but migration from a full .NET framework to .NET Core can be costly and even impossible. Not only because of lack of features, but also because once you…